Hello everybody,
I try to configure a Wireguard Gateway to route my networks through the tunnel to ProtonVPN.
I configured my Firewall as described in the wiki
https://docs.opnsense.org/manual/how-tos/wireguard-selective-routing.html
Yet unfortunaetly there is no internet access through that route
The only thing that looks fishy to me is the lack of "UP" in the Wireguard Status for the peer
Can anybody help to troubleshoot this?
Regards
Look at the logs and post them.
attached
Well, I meant the wireguard logs...
screen shot 2.
delete the top rule (or disable it)
for the IP 4 Lan.net rule. why not change the gateway to protonvpn? reset states and see if it actually works?
then fine tune your alias's / certain computers you want to go out the tunnel
Picture 1 - Wireguard Logs
Picture 2 - Tried changing the Gateway to ProtonVPN, didnt work
interface area doesn't appear to be completed all the way.
have you clicked advanced mode top left? then for DNS put their DNS server and IP address for the gateway address in your configuration file
depending on if you are using ISC or Kea. you will need to add the dns server
interface is setup as described in the wiki here
dns is also setup accordingly in the instance, do you think here lays the problem?
I already tried to use 1.1.1.1, or 10.2.0.1 (privided from protonvpn as DNS)=>didnt work as well
I've never created the gateway manually... I would delete yours and click save> and go to interfaces > the proton WG interface and at the very bottom click Dynamic gateway policy
also on that page I put in MTU of 1320 or up to 1380 and save..
go back to system / gateway / config and see if it shows online. if not open it. click save and see if it comes online for you.
i have 27 proton wan's for production network, one of my client wanted to filter activity on those interfaces. It was year ago or so and same, i was not able to get it work with WG.
Also spoke with proton support and the answer was that wireguard gateways is't the way. I made with openvpn and it's working till now.
I don't pay for proton currently but have two other "providers" where the setup is fairly straightforward and just works